logo

Malspam Campaign Uses DoubleClick Redirects to Deliver .NET Loader

ID: bda0a478-ca07-54cc-a42d-0dc25013b9f8

STIX ID: report--bda0a478-ca07-54cc-a42d-0dc25013b9f8

Feed Name: Cyber Press

Threat Score
78/100

Date Published: 2026-06-06

Date Updated: 2026-06-06

Author: Lucas Martin

...
...

A sophisticated malspam campaign uses DoubleClick redirects and on-the-fly personalized lure pages to bypass email gateways and deliver a five-stage malware chain that culminates in a process-hollowed payload; the .NET loader performs VM/sandbox detection, patches AMSI/ETW, disables Defender, establishes persistence, injects into legitimate signed processes, and communicates with DDNS-based C2 servers. The report provides domains, file paths, hashes, user-agent and other IOCs, plus mitigation recommendations such as blocking script execution, enhanced email sandboxing, and monitoring for suspicious child processes and staging directories.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.